IP Library › Granted Patent US 10,924,468
Granted Patent B2
US 10,924,468 · App. 16/047,109 · Granted Feb 16, 2021

Remote desktop protocol proxy with single sign-on and enforcement support

Inventors: Viswanath Yarangatta Suresh (Bengaluru, IN); Arkesh Kumar (San Jose, CA); Dileep Reddem (San Jose, CA); Anil Kumar Gavini (San Jose, CA)
Assignee: Citrix Systems, Inc.
H04L63/0815H04L63/083
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,924,468
App. No.
16/047,109
Granted
Feb 16, 2021
Kind
B2
Abstract

Described embodiments provide systems and methods for launching a connection to a resource link from a client device. A device can authenticate the client device for access to a plurality of resource links accessible via one or more servers. The device can provide a list of the plurality of resource links responsive to the authentication, and receive a request from the client device, identifying a first resource link to access. The device can cause first authenticated credentials for the first resource link to be stored on the client device responsive to the request. The first authenticated credentials can correspond to the client device and provide access the first resource link. The client device can be configured to launch a connection to the first resource link from the client device using the first authenticated credentials stored on the client device.

Claims (41)

1. A method for launching a connection to a resource link from a client device, the method comprising:

authenticating, by a device intermediary to a client device and one or more servers, the client device for access to a plurality of resource links accessible via the one or more servers, the plurality of resource links include one or more remote desktop protocol (RDP) connections;

providing, by the device to the client device, a list of the plurality of resource links responsive to the authentication;

receiving, by the device, a request from the client device, identifying a first resource link from the plurality of resource links and information indicating at least one server of the one or more servers to establish an RDP connection; and

causing, by the device, first authenticated credentials for the first resource link to be stored on the client device via a script downloaded to the client device from the device and responsive to the request, the first authenticated credentials corresponding to the client device to access the first resource link through the RDP connection via the at least one server of the one or more servers, and wherein the client device is configured to launch a connection to the first resource link from the client device using the first authenticated credentials stored on the client device.

2. The method of claim 1 , further comprising causing, by the device, a plurality of authenticated credentials to be stored on the client device, the client device configured to launch connections to the plurality of resource links using the plurality of authentication credentials provided by the device and stored on the client device.

3. The method of claim 1 , wherein the plurality of resource links include the one or more remote desktop protocol (RDP) connections to the one or more servers.

4. The method of claim 1 , further comprising the connection to the first resource link being launched from the client device via one of a command line or a file using the first authentication credentials stored on the client device and without a prompt for credentials.

5. The method of claim 1 , further comprising:

receiving, by the device, a launch request from the client device for connecting to the first resource link, the launch request including the first authenticated credentials stored on the client device.

6. The method of claim 5 , further comprising:

verifying, by the device, the first authentication credentials from the client device;

identifying, by the device, for the first resource link, a first resource server of the one or more servers from the launch request; and

establishing, by the device, a second connection between the device and the first resource server using second authentication credentials managed by the device to authenticate to the first resource server on behalf of the client device.

7. The method of claim 1 , further comprising:

causing, by the device, the authentication credentials for each of the plurality of resource links to be stored on the client device via scripts provided by the device.

8. The method of claim 1 , wherein the connection to the first resource link is launched from the client device using the first authentication credentials to connect to one of the device or a first resource server of the one or more servers.

9. The method of claim 1 , further comprising authenticating, by the device responsive to the first authentication credentials, one of the client device or a user of the client device to one or more of the servers hosting the plurality of resource links using authentication credentials managed by the device for accessing by one of the client device or the user of the client device the one or more servers, the authentication credentials different from the first authentication credentials.

10. The method of claim 1 , comprising:

establishing, by the device, the connection between the client device and the device using the first authentication credentials and a second connection between the device and the first resource server of the one or more servers providing the first resource link using second authentication credentials managed by the device to authenticate to the first resource server on behalf of the client device; and

applying, by the device, one or more policies to one of the connection or the second connection to control access to the first resource link.

11. A system for launching a connection to a resource link from a client device, the system comprising:

a device intermediary to a client device and a server, the device configured to:

authenticate the client device for access to a plurality of resource links accessible via the one or more servers, the plurality of resource links include one or more remote desktop protocol (RDP) connections;

provide to the client device a list of the plurality of resource links responsive to the authentication;

receive a request from the client device identifying a first resource link from the plurality of resource links and information indicating at least one server of the one or more servers to establish an RDP connection; and

cause first authenticated credentials for the first resource link to be stored on the client device via a script downloaded to the client device from the device and responsive to the request, the first authenticated credentials corresponding to the client device to access the first resource link through the RDP connection via the at least one server of the one or more servers, and wherein the client device is configured to launch a connection to the first resource link from the client device using the first authenticated credentials stored on the client device.

12. The system of claim 11 , wherein the device is further configured to cause a plurality of authenticated credentials to be stored on the client device, the client device configured to launch connections to the plurality of resource links using the plurality of authentication credentials provided by the device and stored on the client device.

13. The system of claim 11 , wherein the plurality of resource links include the one or more remote desktop protocol (RDP) connections to the one or more servers.

14. The system of claim 11 , wherein the connection to the first resource link is launched from the client device via one of a command line or a file using the first authentication credentials stored on the client device and without a prompt for credentials.

15. The system of claim 11 , wherein the device is further configured to receive a launch request from the client device for connecting to the first resource link, the launch request including the first authenticated credentials stored on the client device.

16. The system of claim 15 , wherein the device is further configured to:

verify the first authentication credentials from the client device;

identify a first resource server of the one or more servers for the first resource link from the launch request; and

establish a second connection between the device and the first resource server using second authentication credentials managed by the device to authenticate to the first resource server on behalf of the client device.

17. The system of claim 11 , wherein the device is further configured to cause the authentication credentials for each of the plurality of resource links to be stored on the client device via scripts provided by the device.

18. The system of claim 11 , wherein the connection to the first resource link is launched from the client device using the first authentication credentials to connect to one of the device or a first resource server of the one or more servers.

19. The system of claim 11 , wherein the device is further configured to authenticate, responsive to the first authentication credentials, one of the client device or a user of the client device to one or more of the servers hosting the plurality of resource links using authentication credentials managed by the device for accessing by one of the client device or the user of the client device the one or more servers, wherein the authentication credentials are different from the first authentication credentials.

20. The system of claim 11 , wherein the device is further configured to:

establish the connection between the client device and the device using the first authentication credentials and a second connection between the device and a first resource server of the one or more servers providing the first resource link using second authentication credentials managed by the device to authenticate to the first resource server on behalf of the client device; and

applying, by the device, one or more policies to one of the connection or the second connection to control access to the first resource link.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 31, 2018
From: SURESH, VISWANATH YARANGATTA; KUMAR, ARKESH; REDDEM, DILEEP; GAVINI, ANIL KUMAR
To: CITRIX SYSTEMS, INC.
Reel/Frame 046513/0177 →
Continuity (1)
Related Publication 20200036699A1 · Jan 30, 2020
Cited By (1)
US 12,289,308